URL error when using "goto" function
Reported by
lion.nag...@web.de,
Sep 21 2017
|
||||||
Issue descriptionVULNERABILITY DETAILS I am unsure if its a security relevant bug. When you use the "right click" "goto" function on a link starting with ":https://" (the : before http is relevant, but you could also use a ".", maybe also other characters) it changes the link to https// (see screenshots) The link needs to have a "/" at the and or it does not show the "switch to" I can not think about any real security problem out of it. do you see anything? Contact details (best): l.nagenrauft@it-cube.net VERSION Chrome Version: [61.0.3163.9] stable Operating System: Windows 10 up 2 date REPRODUCTION CASE Please see screenshots. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: [tab, browser, etc.] Crash State: [see link above: stack trace, registers, exception record] Client ID (if relevant): [see link above]
,
Sep 21 2017
,
Sep 22 2017
You are using tags - i dont use tags. See example html file.
,
Sep 22 2017
Thank you for providing more feedback. Adding requester "palmer@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 22 2017
Ahh, I see. Thanks. To reproduce, you have to select the text, and then right-click on it, and then you get a Go To... option. I didn't know about that before. :) Does this happen on mobile, too (long-press)?
,
Sep 25 2017
aurimas, you seem to be the owner of IDS_CONTENT_CONTEXT_GOTOURL (the person who touched chrome/browser/renderer_context_menu/render_view_context_menu.cc last seems not to be on the team any longer?). Could you take a look, or bounce this to someone who can?
,
Sep 25 2017
I no longer work on Chrome and I only touched that file, so you'll have to find someone else to blame :)
,
Sep 26
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by palmer@chromium.org
, Sep 21 2017Summary: URL error when using "goto" function (was: Security: URL Error when using "goto" function)